Impact
A buffer overflow flaw exists where improper bounds checking can lead to corruption of memory. When an application processes malicious data, the overflow causes the target app to terminate unexpectedly, resulting in a denial‑of‑service condition for the user.
Affected Systems
Apple devices running iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), tvOS, visionOS, and watchOS are affected. Versions older than iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2 are vulnerable.
Risk and Exploitability
The CVSS score of 2.8 indicates low severity, and the EPSS score of less than 1% shows a very low exploitation likelihood. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivery of malicious content that an application will ingest, which may come from network traffic or user-provided data; however, details are not explicitly stated and are inferred from the description.
OpenCVE Enrichment